PRIVACY POLICY
COMMITMENT TO DATA PROTECTION
BrosDev Technologies ("BrosDev", "We", "Us", "Our") respects your privacy and is dedicated to managing client information with bank-grade security protocols in compliance with EU General Data Protection Regulation ("GDPR"), California Consumer Privacy Act ("CCPA"), and global cybersecurity standards.
1. Information We Collect
1.1. Directly Provided Information: We collect personal details when you submit consultation forms, subscribe to insights, or enter into engineering contracts (e.g., name, work email, phone number, company name, project specifications).
1.2. Technical & Usage Data: When visiting our platform, we automatically capture IP addresses, browser types, operating systems, referring URLs, and page navigation patterns via aggregated analytical telemetry.
1.3. Zero Sensitive Data Processing: We do not collect or process special categories of personal data (such as health, biometric, genetic, or political data) unless required under a specific HIPAA/FinTech SOW.
2. Legal Basis for Processing (GDPR Art. 6)
2.1. Contract Performance: Processing contact and project details is necessary to execute Master Services Agreements, deliver sprint software builds, and issue billing invoices.
2.2. Legitimate Interests: Processing website analytics and technical telemetry supports network security monitoring, system optimization, and enterprise service enhancements.
2.3. Consent: Where required by law (e.g., newsletter subscriptions or marketing communications), processing is based on explicit opt-in consent.
3. How We Use Collected Information
3.1. To evaluate technical project requirements and schedule developer matching discovery calls.
3.2. To engineer custom web, cloud, and mobile software applications specified under signed Statements of Work.
3.3. Zero Data Monetization Guarantee: BrosDev never sells, rents, leases, or trades client personal data or proprietary repository code bases to third-party ad networks or data brokers.
4. Enterprise Data Security & ISO / SOC-2 Compliance
4.1. Encryption Standards: All data in transit is encrypted using TLS 1.3 encryption protocols. Sensitive client data at rest is secured via AES-256 hardware cryptographic encryption.
4.2. Access Control: Engineering team access to client repositories and cloud VPCs is enforced through multi-factor authentication (MFA), hardware security keys, and role-based principle of least privilege.
4.3. Audit & Vulnerability Testing: We perform routine automated static code analysis (SAST), dependency vulnerability scanning, and third-party penetration testing.
5. Data Retention & Archival Policies
5.1. Personal data and project communication records are retained for as long as necessary to fulfill the operational purposes set forth in active contracts.
5.2. Following project completion or account termination, client project repositories and temporary staging environments are scrubbed and permanently deleted within ninety (90) days upon written request.
6. Third-Party Subprocessors & Infrastructure
6.1. BrosDev utilizes enterprise cloud infrastructure providers (e.g., AWS, Vercel, GitHub, Cloudflare, Google Cloud Platform) to host platform infrastructure and run automated CI/CD deployment pipelines.
6.2. All third-party subprocessors undergo rigorous vendor security evaluations and are bound by Data Processing Addendums (DPAs) reflecting equivalent data safety standard guarantees.
7. International Data Transfers (EU-US & Global Frameworks)
7.1. For cross-border data transfers originating from the European Economic Area (EEA), UK, or Switzerland to global delivery centers, BrosDev implements Standard Contractual Clauses (SCCs) approved by the European Commission.
8. Your Data Privacy Rights (GDPR & CCPA)
8.1. Right to Access & Portability: Request copies of personal data held by BrosDev in a structured, machine-readable format.
8.2. Right to Erasure ("Right to be Forgotten"): Request the permanent deletion of personal information where no overriding legal obligation exists.
8.3. Right to Rectification: Request correction of inaccurate or incomplete personal records.
9. Cookies & Analytics Telemetry Policy
9.1. We use essential session cookies to maintain platform security, language localization preferences (EN, DE, FR, ES, HI), and user authentication states.
9.2. You can manage or disable cookie tracking at any time through your web browser preferences or consent banner controls.
10. Contact & Data Protection Officer (DPO) Inquiries
If you have questions regarding this Privacy Policy, wish to exercise your statutory privacy rights, or submit a Data Subject Access Request (DSAR), please contact our Data Protection Officer:
BROSDEV DATA PROTECTION OFFICER
Email: dpo@brosdev.com / privacy@brosdev.com
Address: GIFT City / Infocity, Gujarat 382007, India
HAVE PRIVACY OR COMPLIANCE QUESTIONS?
Our DPO responds within 24 hours at privacy@brosdev.com